CVE-2022-28796: Use After Free
jbd2journalwaitupdates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transactiont race condition.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-28796?
CVE-2022-28796 is a vulnerability in the Linux kernel before version 5.17.1 that allows a use-after-free caused by a transaction_t race condition in the jbd2_journal_wait_updates function in fs/jbd2/transaction.c.
How severe is CVE-2022-28796?
CVE-2022-28796 is considered high severity with a CVSS score of 7.
Which software versions are affected by CVE-2022-28796?
The Linux kernel versions before 5.17.1, Redhat Enterprise Linux versions 6.0 and 7.0, and Fedoraproject Fedora version 35 are affected by CVE-2022-28796.
How can I fix CVE-2022-28796?
To fix CVE-2022-28796, it is recommended to update to the Linux kernel version 5.17.1 or later.
Where can I find more information about CVE-2022-28796?
You can find more information about CVE-2022-28796 in the following references: [Link 1](https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.17.1), [Link 2](https://github.com/torvalds/linux/commit/cc16eecae687912238ee6efbff71ad31e2bc414e), [Link 3](https://security.netapp.com/advisory/ntap-20220506-0006/).